Encoded PowerShell Net Commands
Detects PowerShell commands using encoded command-line arguments to execute 'net user', 'net group', or 'net share' commands. This technique is often used by adversaries to obfuscate their actions and evade detection.
Microsoft Sentinel (KQL)

